{"schema_version":"1.9.0","id":"CVE-2023-32732","published":"2023-06-09T10:48:15.075Z","modified":"2026-08-12T13:34:26.189819Z","aliases":["GHSA-9hxf-ppjv-w6rq","PYSEC-2026-1426"],"related":["CGA-9whx-98qm-q5pf","SUSE-SU-2024:0573-1","openSUSE-SU-2024:13621-1","openSUSE-SU-2024:13634-1"],"summary":"Denial-of-Service in gRPC","details":"gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in  https://github.com/grpc/grpc/pull/32309 https://www.google.com/url","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc","events":[{"introduced":"358bfb581feeda5bf17dd3b96da1074d84a6ef8d"},{"fixed":"6847e05dbb8088a918f06e2231a405942b5c002d"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.53"},{"fixed":"1.54"},{"introduced":"0"},{"fixed":"1.53.0"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}},{"type":"GIT","repo":"https://github.com/grpc/grpc-go","events":[{"introduced":"0"},{"fixed":"357d7afc43fe0df74205b797525818fca8cd8f53"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.53.0"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/grpc/grpc-java","events":[{"introduced":"0"},{"fixed":"4ca6de0e8e52386301890b2860fb7a9a7c2c9b7c"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.53.0"}],"source":"CPE_RANGE"}}],"versions":["v1.52.0-dev","v1.51.0-dev","v1.50.0-dev","v1.49.0-dev","v1.48.0-dev","v1.47.0-dev","v1.46.0-dev","v1.45.0-dev","cmd/protoc-gen-go-grpc/v1.2.0","v1.44.0-dev","v1.43.0-dev","v1.42.0-dev","v1.41.0-dev","v1.40.0-dev","v1.39.0-dev","v1.38.0-dev","v1.37.0-dev","cmd/protoc-gen-go-grpc/v1.1.0","v1.36.0-dev","v1.35.0-dev","cmd/protoc-gen-go-grpc/v1.0.1","v1.34.0-dev","cmd/protoc-gen-go-grpc/v1.0.0","v1.33.0-dev","v1.32.0-dev","v1.31.0-dev","v1.30.0-dev.1","v1.30.0-dev","v1.29.0-dev","v1.28.0-pre","v1.27.0-pre","v1.2.0","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1-GA","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32732.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["153505462668301892070772696189317306250","40520222390141456988000868829229775555","78570411478650308013931737040086710778","60539704661294299732272537641085493035"],"threshold":0.9},"id":"CVE-2023-32732-c5f45506","signature_type":"Line","signature_version":"v1","source":"https://github.com/grpc/grpc-java/commit/4ca6de0e8e52386301890b2860fb7a9a7c2c9b7c","target":{"file":"core/src/main/java/io/grpc/internal/GrpcUtil.java"}}],"vanir_signatures_modified":"2026-08-12T13:34:26Z"}}],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/37IDNVY5AWVH7JDMM2SDTL24ZPPZJNSY/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VWE44J5FG7THHL7XVEVTNIGEYBNKJBLL/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32732.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32732"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/32309"}],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-440"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32732.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}